diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 6214a354d2..c282593bbc 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -126,12 +126,12 @@ jobs: with: persist-credentials: false show-progress: false - # include the local composite actions, so that actionlint validates + # include the local composite actions, so that jactionlint validates # their metadata, and zizmor audits them sparse-checkout: .github/ - name: Check workflow files - uses: docker://rhysd/actionlint:1.7.12@sha256:b1934ee5f1c509618f2508e6eb47ee0d3520686341fec936f3b79331f9315667 + uses: docker://ghcr.io/jdx/jactionlint:1.8.2@sha256:5515b269082f92ee0962ccc236df3300113aedcd4008a2aad5ad0903680b7c67 with: args: -color -ignore "invalid activity type \"destroyed\" for \"merge_group\" Webhook event. available types are \"checks_requested\"" diff --git a/AGENTS.md b/AGENTS.md index 680fb3a135..581c3ea73c 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -44,6 +44,8 @@ All tooling runs through `pnpm`: The container tests build the whole image, so they take several minutes. +`jactionlint` lints the GitHub workflows and local actions, install it with `mise install`. + ## Tool installers When adding or changing a tool installer, follow the [tool installer best practices](./docs/tool-installer-best-practices.md). diff --git a/mise.toml b/mise.toml index 7e0c954eb7..79ff2481f8 100644 --- a/mise.toml +++ b/mise.toml @@ -1,3 +1,4 @@ [tools] +jactionlint = "1.8.2" node = "24.21.0" pnpm = "12.10.0"